Skip to content

CAA Extensions for the Tor Rendezvous Specification

Q Misell requested to merge TheEnbyperor/tor:caa into main

This MR implements the 343-rend-caa proposal, in support of draft-misell-acme-onion.

It allows adding CAA records (as in the DNS) to hidden service descriptors to aid the security of issuing TLS certificates to .onion Special-use Domain Names. Example:

HiddenServiceDir /var/lib/tor/test_hs/
HiddenServicePort 80
HiddenServiceCAA 0 issue ""
HiddenServiceCAA 0 iodef ""
HiddenServiceCAA 128 validationmethods "onion-csr-01"

Further details about this project can be found at

Merge request reports